nerdexam
Microsoft

SC-200 · Question #431

You have a Microsoft 365 subscription. The subscription contains 500 devices that are onboarded to Microsoft Defender for Endpoint. You have an Azure subscription that contains a Microsoft Sentinel…

The correct answer is C. a device group. To automatically remediate threats for a selected group of devices in Microsoft Defender for Endpoint, you should create a device group in the Microsoft Defender portal and set its Automation level to Full - remediate threats automatically. This configuration enables automated…

Submitted by omar99· Apr 18, 2026

Question

You have a Microsoft 365 subscription. The subscription contains 500 devices that are onboarded to Microsoft Defender for Endpoint. You have an Azure subscription that contains a Microsoft Sentinel workspace. You need to run a pilot on 50 devices that will remediate threats automatically. The solution must meet the following requirements:

  • Minimize the impact on devices that are excluded from the pilot.
  • Minimize administrative effort.

What should you configure first?

Options

  • Aa playbook
  • Ban endpoint security policy
  • Ca device group
  • Dan automation rule

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    82% (28)
  • D
    9% (3)

Explanation

To automatically remediate threats for a selected group of devices in Microsoft Defender for Endpoint, you should create a device group in the Microsoft Defender portal and set its Automation level to Full - remediate threats automatically. This configuration enables automated actions to be performed on entities considered malicious within that specific device group. https://learn.microsoft.com/en-us/defender-endpoint/configure-automated-investigations-

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice